4CINFOTECH · 4C PULSE

Security at 4C Pulse

A clear overview of the security layers, safeguards, and planned protections behind 4C Pulse. We distinguish current foundations from features that remain on the roadmap.

Your conversations deserve careful protection.

4C Pulse is developed with security as a layered responsibility: protecting connections, controlling access, safeguarding devices, and operating the service responsibly. The protections available to you can vary by app version.

How the system is structured

Android app → TLS-protected connection (HTTPS/WSS) → Apache web server → Node.js application service → MySQL database

Each layer has a different role. TLS helps protect information while it travels between the app and service. The application layer handles requests and access decisions. The database stores service data and should only be accessible through appropriately restricted server-side permissions.

Transport protection

Production web and messaging connections should use HTTPS and secure WebSocket connections (WSS) so data is encrypted in transit between the app and the service.

Account and application access

Authentication establishes an account or session, while authorization determines which actions and resources that session may access. These checks must be enforced by the server, not only by the app interface.

Server and database

Server-side controls should limit database privileges, protect configuration secrets, validate requests, and prevent unauthorized access to messages and media.

Device safeguards

Android platform protections, including Android Keystore where implemented, can help protect cryptographic keys on a device. They do not by themselves provide end-to-end encryption for messages.

Current protections and ongoing work

Security is continuous work rather than a single feature. We publish release information to help explain what is available and what is still being developed.

  • Secure transport: HTTPS/WSS is the intended production transport for app-to-service communication.
  • Access controls: authentication, authorization, server-side validation, and least-privilege database access are core requirements for the service.
  • Operational safeguards: backup protection, monitoring, restricted administrative access, and audit logging should be maintained and reviewed as the service evolves.
  • Advanced message security: end-to-end encryption (E2EE), device identity, and key-management capabilities must not be assumed to be available unless a specific production release explicitly confirms them.
Important distinction

HTTPS/WSS protects data in transit between endpoints. It does not, by itself, mean messages are end-to-end encrypted. This page does not claim independent security certification or that every listed control has been independently audited.

What you can do

Report a security concern

If you believe you have found a security issue, please share a clear description of the issue and the steps needed to reproduce it. Avoid including other people's private messages, passwords, authentication codes, or unnecessary personal information.

Contact 4C Pulse about a security concern.

Security information is reviewed as the product changes. Feature availability may differ by release; consult the latest announcements for current product updates.